Shadow AI and data leakage
Samsung: source code pasted into ChatGPT
In early 2023, shortly after Samsung permitted internal ChatGPT use, engineers pasted proprietary source code and the transcript of a confidential meeting into the tool in three separate incidents within about three weeks. Samsung responded by banning generative AI tools on company devices.
The governance gap
Employees had a powerful tool and no rules about what data could go into it. Nobody had decided, so each engineer decided alone, under deadline pressure.
What governance looks like
A written rule that source code, client data, and confidential information never go into unapproved AI tools. Approved business-grade accounts for the tasks people actually need. Data loss prevention that catches sensitive content before it leaves.